api: port: 5300 webhook_prefix: 'http://127.0.0.1:5300' extra_webhook_prefix: '' # Canonical browser origin when WebUI and API use different origins in # development (for example http://localhost:3000). Production bundled UI # may leave this empty when webhook_prefix already has the browser origin. # OAuth redirects trust only these server-side values, never request Host # or Origin headers. webui_url: '' # Global API key for the HTTP service API and the MCP server. When set to a # non-empty string, this key is accepted anywhere a web-UI-created API key is # accepted (X-API-Key header or "Authorization: Bearer "), WITHOUT any # login session and without a database record. Leave empty to disable. # Keep this value secret; only enable it on trusted/internal deployments. global_api_key: '' command: enable: true prefix: - '!' - ! privilege: {} concurrency: pipeline: 20 session: 1 proxy: http: '' https: '' system: instance_id: '' edition: community recovery_key: '' allow_modify_login_info: true disabled_adapters: [] # Public outbound IP addresses of this LangBot deployment. Some platforms # (e.g. WeCom, WeChat Official Account, QQ Official API) require the # caller's IPs to be added to their trusted-IP / IP-whitelist settings. # When set, the web UI shows these IPs on the bot config form of such # adapters. Also settable via the SYSTEM__OUTBOUND_IPS env var # (comma-separated). Empty list = hidden in the web UI. outbound_ips: [] limitation: max_bots: -1 max_pipelines: -1 max_extensions: -1 # When set to a non-empty string, every pipeline is forced to use this # Box sandbox-scope template regardless of its own configuration, and # the per-pipeline "Sandbox Scope" selector is locked in the web UI. # Used by SaaS deployments to confine a tenant to a single shared # sandbox (set to '{global}'). Empty string = no restriction. force_box_session_id_template: '' task_retention: # Keep at most this many completed async task records in memory completed_limit: 200 jwt: expire: 604800 secret: '' database: use: sqlite sqlite: path: 'data/langbot.db' postgresql: # Optional SQLAlchemy URL (postgresql[+asyncpg]://...). When set, it # overrides the structured fields and preserves TLS/query options. url: '' host: '127.0.0.1' port: 5432 user: 'postgres' password: 'postgres' database: 'postgres' cloud_migration: # `langbot migrate --cloud` reads an operator-only PostgreSQL DSN from # this environment variable. The operator role must differ from the # runtime role above; never put its password in this file or CLI args. operator_dsn_env: 'LANGBOT_CLOUD_MIGRATION_DSN' vdb: use: chroma qdrant: url: '' host: localhost port: 6333 api_key: '' seekdb: mode: embedded # 'embedded' or 'server' # Embedded mode options: path: './data/seekdb' database: 'langbot' # Server mode options (used when mode='server'): host: 'localhost' port: 2881 user: 'root' password: '' tenant: '' # Optional, for OceanBase server milvus: uri: 'http://127.0.0.1:19530' token: '' db_name: '' pgvector: # SaaS/shared-schema deployments reuse database.postgresql. OSS can # keep this false when deliberately using an external pgvector DB. use_business_database: false # Release migrations create one partial ANN index per enabled value. allowed_dimensions: [384, 512, 768, 1024, 1536] host: '127.0.0.1' port: 5433 database: 'langbot' user: 'postgres' password: 'postgres' valkey_search: host: 'localhost' port: 6379 # integration tests use 6380 -> valkey/valkey-bundle:9.1.0 db: 0 password: '' # optional (toB auth) username: '' # optional (ACL user, toB) tls: false # optional (toB/SaaS) index_algorithm: 'HNSW' # HNSW | FLAT distance_metric: 'COSINE' # COSINE | L2 | IP request_timeout: 5000 # per-request timeout in ms (glide default 250ms is too low for KNN) storage: use: local cleanup: # Enable periodic cleanup of local/S3 uploaded files and old log files enabled: true # Cleanup check interval in hours check_interval_hours: 1 # Root-level uploaded files older than this will be deleted uploaded_file_retention_days: 7 # LangBot log files older than this many days will be deleted log_retention_days: 3 s3: endpoint_url: '' access_key_id: '' secret_access_key: '' region: 'us-east-1' bucket: 'langbot-storage' plugin: enable: true runtime_ws_url: 'ws://langbot_plugin_runtime:5400/control/ws' enable_marketplace: true display_plugin_debug_url: 'ws://localhost:5401/plugin/debug/ws' worker: # Instance-wide maximum for every plugin installation. Plugin # manifests cannot raise or override these limits. max_cpus: 1.0 max_memory_mb: 512 max_pids: 128 max_open_files: 256 max_file_size_mb: 512 # Cloud shared Runtime sets this to true and fails closed unless # delegated cgroup v2 controllers are available. require_hard_limits: false binary_storage: # Max bytes for a single plugin binary storage value max_value_bytes: 10485760 mcp: stdio: # Independent gate for local stdio MCP transports. Cloud v2 sets # MCP__STDIO__ENABLED=false even when Box Runtime is available. enabled: true monitoring: auto_cleanup: # Enable automatic cleanup of expired monitoring records enabled: true # Retention period in days, records older than this will be deleted retention_days: 30 # Cleanup check interval in hours check_interval_hours: 1 # Number of expired rows to delete per table batch delete_batch_size: 1000 box: # Master switch for the Box sandbox runtime. When false, LangBot does NOT # attempt to connect to a remote Box runtime nor start a local stdio Box # subprocess. Disabling Box also disables every feature that depends on it: # the native sandbox tools (exec/read/write/edit/glob/grep), the activate # skill tool, skill add/edit, and stdio-mode MCP servers. Skills can still # be listed read-only and http/sse MCP servers continue to work. enabled: true backend: 'local' # 'local' (Docker/nsjail), 'docker', 'nsjail', or 'e2b'. Can be written via BOX__BACKEND. runtime: # External WebSocket runtimes also require LANGBOT_BOX_CONTROL_TOKEN in # both LangBot and Box. Keep the shared secret out of this config file. endpoint: '' # External Box Runtime base URL, e.g. 'ws://127.0.0.1:5410'. Leave empty for local auto-managed runtime. # Cloud v2 overrides these values through the instance config/environment. # OSS keeps admission disabled and preserves the existing multi-session # local behavior. These limits are Runtime-owned and cannot be relaxed by # a pipeline, Workspace entitlement, or tool call. admission: required: false logical_session_id: 'global' required_backend: 'nsjail' max_sessions: 1 max_managed_processes: 0 max_grant_ttl_sec: 300 max_timeout_sec: 120 cpus: 1.0 memory_mb: 512 pids_limit: 128 read_only_rootfs: true # OSS admission-disabled mode uses 0 for unlimited compatibility. # Cloud bootstrap requires a positive hard quota. workspace_quota_mb: 0 readiness_cache_sec: 15 local: profile: 'default' image: '' # Custom local sandbox image. Leave empty to use the profile default. host_root: './data/box' # Base host directory for local workspace mounts. Docker deployments should override this with an absolute host path. default_workspace: '' # Defaults to '/default'. Relative paths are resolved under host_root. skills_root: 'skills' # Box-owned skill package directory. Relative paths are resolved under host_root. allowed_mount_roots: # Defaults to [''] when left empty. - './data/box' - '/tmp' workspace_quota_mb: null # Optional disk quota override (>= 0). null = profile default. # Default nsjail cgroup memory limit for each MCP stdio server process, in MB. # Node.js MCP servers (npx/bunx) need more memory than Python ones because V8 # and WebAssembly modules (e.g. undici llhttp) reserve large virtual address # space at startup. Setting this too low causes processes to be killed with # return_code=137 (OOM kill); the symptom is "Box managed process exited # unexpectedly" in the logs. Raise on machines with ample RAM; lower only if # you run exclusively Python (uvx) MCP servers. # Can also be set via BOX__DEFAULT_MEMORY_MB. Default: 1536. default_memory_mb: 1536 docker: cpu_limit_enabled: true # When false, Docker sandbox containers are started without --cpus. Memory and PID limits still apply. e2b: api_key: '' # Can also be set via E2B_API_KEY env var. api_url: '' # Custom API URL for self-hosted deployments. template: '' # Default template ID (e.g. 'base', 'python-3.11'). space: # Space service URL for OAuth and API url: 'https://space.langbot.app' # Space API URL for model requests (MaaS) models_gateway_api_url: 'https://api.langbot.cloud/v1' # OAuth authorization page URL (user will be redirected here) oauth_authorize_url: 'https://space.langbot.app/auth/authorize' disable_models_service: false disable_telemetry: false